Expand the common DKIM selector probe list - #12
Open
sage-s11 wants to merge 1 commit into
Open
Conversation
Probe additional stable, documented selectors used by major providers so DKIM presence is less often reported as undetected. Skip per-tenant dynamic selectors.
sanmaxdev
approved these changes
Aug 30, 2026
sanmaxdev
left a comment
Owner
There was a problem hiding this comment.
Checked the expanded selector set against issue #7 and the passive lookup path. The change stays scoped and preserves inconclusive handling for misses.
Passed:
ruff check .mypypytest -q --cov=sentineldeck --cov-fail-under=75(261 passed, 81.09% coverage)bandit -r src -c pyproject.tomlgit diff --check origin/main...HEAD
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Probe additional stable, documented selectors used by major providers so DKIM presence is less often reported as undetected. Skip per-tenant dynamic selectors.
Summary
DKIM presence is probed from
COMMON_DKIM_SELECTORSinsrc/sentineldeck/scanners/email_security.py. A miss is inconclusive, so a short list produces false "not detected" results for domains that only publish a well-known provider selector we were not checking.This expands the list with static, publicly documented selectors used by major providers (Google Workspace, Microsoft 365, Mailchimp, Mandrill, SendGrid, Zoho, Proton Mail, Fastmail, Apple iCloud, Yahoo/AOL legacy, Zendesk, Brevo). Each entry has a short provider comment. Per-tenant / generated selectors are still omitted (Amazon SES tokens, Postmark dated selectors, HubSpot
hs1-<portalId>, etc.).Closes #7
Changes
COMMON_DKIM_SELECTORSwith documented static selectors andprovider comments.
documented names.
Checklist
ruff check .passespytest -qpasses